Live data from Hacker News

The OPM Data Breach [pdf]

oversight.house.gov

61–70 of 131 posts

Re: The OPM Data Breach [pdf]

#61
post #4

"Additionally, fingerprint data of 5.6 million of these individuals was stolen." They'll need to change their fingerprints immediately!

I'd like to see YYYY-04-01 RFC on biometrics authenticator expiration protocols.

"As an alternative, users may keep all their fingers in a fingerprint safe and secure them all with a single retina scan, which they can use to open the safe each time they need to use a finger."

Re: The OPM Data Breach [pdf]

#62

Earlier quoted context omitted.

>It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Damn right. This is one of the aspects of the Snowden leaks that was underplayed. The NSA seems to think th…

Exactly this. The US government thinks about computer security as a kind of war - cyberwar - and for better or for worse it has adapted the mindset that "security by demonstrated capability to drop scary bombs with brutal precision and efficiency" is more realistic than "security by making every building bomb proof." Geopolitics these days isn't about impenetrable borders, it's about deterrence by ability to project…

Re-orienting the NSA's mission to focus on improving security through public research and technology transfer (like SELinux) is the most viable option for stopping the current arms race. There seem to be a shortage of people at the NSA who have the visionary power to imagine a future in which computing is secure. Which is a shame, because it is a future we can realize; the building blocks are here.

Re: The OPM Data Breach [pdf]

#63

Earlier quoted context omitted.

What about things the US Digital Service or 18F? The image they present is that those teams are different and outside the standard government bureaucracy. I'm skeptical.

Employee of 18F here, speaking unofficially. We care a lot about security - both from the technical side and from the policy compliance side!

How was recruitment?. Someone I know tried to get a got job there, got stuck in the queue forever. Was told to wait months. So eventually gave up and took another job.

Re: The OPM Data Breach [pdf]

#64
post #4

"Additionally, fingerprint data of 5.6 million of these individuals was stolen." They'll need to change their fingerprints immediately!

The letter they sent me claimed that there is currently no way to create fake fingerprints, so there's nothing to be worried about, 2 years of identity theft monitoring is good enough.

Re: The OPM Data Breach [pdf]

#65
post #11

If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…

> It seems NSA has spent all its budget on cool hacking tools and programs From the report: On March 20, 2014, US-CERT notified OPM that a third party had reported data exfiltration from the OPM's network. I think it's likely it was NSA that made the notification. Maybe not. Either way, what further could NSA have done about it? The NSA can't make another federal agency improve its computer security. At best it can p…

> The NSA can't make another federal agency improve its computer security.

Maybe not directly. But the NSA could play a much more positive role in information security generally by moving out of the shadows and making more of its research public. The expertise that the NSA has acquired in securing information needs to be widely disseminated to work its way into engineering curricula and praxis, and that won't happen as long as the NSA communicates by whispering.

Re: The OPM Data Breach [pdf]

#67
post #11

If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…

> Yet the all SF-86 forms

Not quite all of them. OPM doesn't seem to keep track of any paper SF-86s that were phased out in favor of the first web site iteration around 2001. Those earlier records may be safe. The image PDF isn't searchable so I couldn't confirm this.

Re: The OPM Data Breach [pdf]

#68
post #11

If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…

After 28 years of DoD service, civilian engineer, I just called it quits. I got tired of the retaliation for turning in security violations. The last one: sharing of passwords on a secured network. One violator's response: Where is it written we cannot share passwords? Why the retaliation? It portrays a bad image. Nice!

Sounds like one of those situations where you're damned if you do and damned if you don't. Even the most eloquent bitchslap directed at such users, even if you disguise it as user education, can still cause strife. :/

Re: The OPM Data Breach [pdf]

#69
post #11

If only we had an agency in charge of protecting and securing these kinds of systems. It seems NSA has spent all its budget on cool hacking tools and programs, exploiting hard drive firmware and routers and other crap. Yet the all SF-86 forms (except CIA's +) got stolen right under our noses. But again, nobody is going to feel cool defending and securing stuff, everyone wants to be on red team. Stolen stuff includes…

Correct me if I'm wrong, but I thought NSA is only in charge of protecting classified systems. OPM data wasn't in a classified system.

Re: The OPM Data Breach [pdf]

#70

> The Exfiltration of the Security Clearance Files Could Have Been Prevented. TL;DR, there were two intrusion actors that were acting in concert. After being notified by US-CERT of exfiltration activity from the OPM network, OPM monitored the first one, who conducted the initial breach (use of contractor login credentials) and then performed survey of their network. They attempted to flush out her malware but failed…

" and still ignored/tabled by the CIO, Donna Seymour. "

Does she still have that job? If so.. ugh.

Post reply on HN